In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's /login endpoint.
/login
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow/PYSEC-2022-42984.yaml"